Please report suspected vulnerabilities privately via GitHub Security Advisories. Do not open a public issue for security reports.
You should receive an acknowledgement within 7 days. Please include a minimal reproduction and the commit or release you tested.
- This is a local-first tool maintained by one person; there is no bug bounty.
- Supported target: the default branch and the latest tagged release (if any).
- Fixes ship as ordinary commits/releases once verified; coordinated disclosure timelines are best-effort.